Related Threat Clusters
-
Persistent Firestarter Malware Targets Cisco Firepower Devices in US Agencies
A sophisticated backdoor malware named Firestarter has been discovered on Cisco Firepower devices, attributed to the state-sponsored threat actor UAT-4356. The malware exploits two vulnerabilities, CVE-2025-20333 and…
37 articles · Updated April 23, 2026 -
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
16 articles · Updated July 22, 2026 -
North Korean Hackers Utilize EtherHiding for Cryptocurrency Theft
The Google Threat Intelligence Group (GTIG) reports that North Korean threat actor UNC5342 has adopted a new technique called EtherHiding to deliver malware and facilitate cryptocurrency theft. This method embeds…
3 articles · Updated May 26, 2026 -
Void Dokkaebi's Malware Campaign Exploits Developer Repositories via Fake Job Interviews
Void Dokkaebi, a North Korean threat actor, has escalated its malware distribution tactics by using fake job interviews to compromise software developers. This campaign, known as the 'Contagious Interview,' targets…
22 articles · Updated April 22, 2026 -
North Korean Hackers Use SVG Steganography in Job Scam Malware Campaign
DPRK-aligned hackers have launched a campaign known as Contagious Interview, utilizing steganography to hide malware within SVG flag images. This malware targets developers through fake job postings and coding…
4 articles · Updated July 19, 2026 -
GrayAlpha Threat Actor Uses MaskBat Loader for NetSupport RAT Deployments
Insikt Group identified GrayAlpha, a threat actor linked to FIN7, utilizing a custom loader named MaskBat to deploy NetSupport RAT through various infection vectors. These include fake browser update pages, fake 7-Zip…
2 articles · Updated August 6, 2026 -
North Korea-linked EtherRAT Malware Exploits React2Shell Vulnerability
North Korea-linked hackers have exploited a critical flaw in web applications using a new malware called EtherRAT. This remote access trojan employs Ethereum smart contracts for communication and utilizes multiple Linux…
3 articles · Updated December 10, 2025 -
Cyber Adversaries Exploit File Enumeration and Data Collection Techniques
Recent reports detail the tactics employed by various cyber adversaries to enumerate files and directories on compromised systems. Adversaries utilize command shell utilities and custom tools to gather sensitive…
2 articles · Updated April 22, 2026 -
Cyber Threat Landscape in Finance Sector: Key Trends Identified
The financial sector, including banks and cryptocurrency platforms, is facing a complex cyber threat landscape. This sector's heavy reliance on digital infrastructure makes it a prime target for both financially…
3 articles · Updated January 28, 2026 -
North Korea's Contagious Interview Campaign Uses JSON for Malware Distribution
North Korean threat actors are utilizing JSON storage services to distribute malware through the Contagious Interview campaign, which has been active since 2023. They impersonate hiring professionals to lure developers…
2 articles · Updated November 17, 2025
Recent Intelligence Reports
- T1036 — attack.mitre.org · August 7, 2026
- 003 — attack.mitre.org · July 23, 2026
- Contagious Interview Malware Svg Steganography — www.elastic.co · July 20, 2026
- Dprk Adopts Etherhiding — cloud.google.com · May 26, 2026
- T1082 — attack.mitre.org · April 24, 2026
- Void Dokkaebi Uses Fake Job Interview Lure to Spread Malware via Code Repositories — Trendmicro · April 22, 2026
- T1005 — attack.mitre.org · April 22, 2026
- T1083 — attack.mitre.org · April 22, 2026